Embedding More Knowledge: Strategic Graph Masking Based Advanced Persistent Threats Detection

Junbo Jia, Li Yang, Lu Zhou, Anyuan Sang, Huipeng Yang, Ao Wang · 2025

Advanced Persistent Threats (APTs) have become increasingly frequent, presenting substantial challenges to the management of network services. Using provenance graphs for log analysis has become a common approach in APT detection. However, existing research has two shortcomings: it does not fully utilize richer contextual semantic information and fails to effectively respond to unknown attacks. This paper presents SGAM, an accurate and fast APT detection framework. SGAM enhances accuracy through a training process driven by a masking strategy. The masking strategy includes the selection of masked nodes and a more robust training approach. SGAM incorporates the importance of provenance graph nodes into the masking strategy, gradually increasing the significance of the masked information during training, allowing the model to learn more critical node features. This enables the model to extract deeper contextual semantic information. In anomaly detection, SGAM employs an unsupervised method to ensure effective detection of unknown attacks while improving detection efficiency. We evaluated SGAM on three widely used datasets, and the results indicate that SGAM demonstrates outstanding detection performance across all scenarios, outperforming existing methods. Additionally, experiments show that SGAM can mitigate the impact of concept drift to some extent.

Read the paper · More papers on PaperTik